Apex Aerospace is designing a Microsoft Entra ID identity strategy. The organization plans to implement a strict Conditional Access policy that requires Multi-Factor Authentication (MFA) for all administrative roles. The security team wants to ensure that administrators can still access the tenant to resolve configuration issues or during a cloud-based MFA service outage. Which design option should you recommend?
- AConfigure all administrative roles as eligible for activation in Microsoft Entra Privileged Identity Management (PIM) and rely on the activation workflow without any Conditional Access policy exclusions.
- Create two dedicated emergency access accounts, assign them the Global Administrator role, and exclude them from the Conditional Access policies requiring MFA.Cevap
- CDeploy an Active Directory Federation Services (AD FS) infrastructure to federate the tenant, routing all administrator authentication requests to on-premises servers to bypass Azure MFA.
- DConfigure all administrator accounts with permanently active role assignments in Privileged Identity Management (PIM) to ensure they bypass the need for elevation during a disaster.
Cevap
Create two dedicated emergency access accounts, assign them the Global Administrator role, and exclude them from the Conditional Access policies requiring MFA.
Creating dedicated emergency access accounts (break-glass accounts) and excluding them from the Conditional Access policies that enforce MFA ensures that administrators have a fallback mechanism to sign in and resolve configuration issues or outages without requiring MFA.
Adım Adım Çözüm
Anahtar Kavram
Microsoft Entra ID emergency access accounts
Tahmini Süre:2m 0s